Cyber Security Brief — 2026-08-29
Today's brief: McKesson discloses breach after ShinyHunters claims patient data theft, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- McKesson discloses breach after ShinyHunters claims patient data theft (BleepingComputer) — Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extorti…
- Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network (The Hacker News) — Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortio…
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable (The Hacker News) — Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability,…
- PaperCut releases second emergency patch for exploited flaws (BleepingComputer) — PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to by…
- GiveWP WordPress donation plugin flaw lets hackers execute server commands (BleepingComputer) — A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
Newly published, high-severity CVEs
- CVE-2026-82222 (CVSS 10, CRITICAL) — Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
- CVE-2026-76581 (CVSS 9.8, CRITICAL) — The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthentica…
- CVE-2026-78032 (CVSS 9.8, CRITICAL) — SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
- CVE-2026-42007 (CVSS 9.1, CRITICAL) — An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 3 Security Score scans across our customers in the past 7 days.
- medium: 4
- info: 19
- high: 7
- low: 9
Most common issues:
- Cross-origin stylesheet loaded without Subresource Integrity (seen 6x)
- DKIM not detected at common selectors (seen 3x)
- No DMARC record (seen 3x)
- DNSSEC not detected (seen 3x)
- Missing recommended headers (1) (seen 2x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan